Improper Neutralization of Special Elements in Data Query Logic in Flowise - CVE-2026-41274

 

Improper Neutralization of Special Elements in Data Query Logic in Flowise - CVE-2026-41274

Published: April 20, 2026


Vulnerability identifier: #VU126602
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-41274
CWE-ID: CWE-943
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary cypher commands on the underlying Neo4j database.

The vulnerability exists due to improper neutralization of special elements in data query logic in the GraphCypherQAChain run method when handling user-supplied input through the prediction endpoint. A remote user can send a specially crafted request to execute arbitrary cypher commands on the underlying Neo4j database.

Exploitation requires a chatflow that includes the Graph Cypher QA Chain node and is connected to a Neo4j Graph node with valid credentials.


Affected software

Flowise

How to mitigate CVE-2026-41274

Install security update from vendor's website.

Flowise - update to 3.1.0

External References

Related Security Bulletins